When curl is instructed to download content using the metalink feature, the contents is verified against a hash provided in the metalink XML file. There's a risk the user doesn't notice the message and instead assumes the file is fine.
This flaw has existed in curl since commit [b5fdbe848bc3d](https://github.com/curl/curl/commit/b5fdbe848bc3d) in curl 7.27.0, released on July 27, 2012.
Created curl tracking bugs for this issue: Affects: fedora-all [bug 1984325]
Upstream advisory: https://curl.se/docs/CVE-2021-22922.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:3582 https://access.redhat.com/errata/RHSA-2021:3582
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-22922
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2021:3903 https://access.redhat.com/errata/RHSA-2021:3903